Invention Grant
- Patent Title: Heuristic malware detection
- Patent Title (中): 启发式恶意软件检测
-
Application No.: US11609170Application Date: 2006-12-11
-
Publication No.: US08091127B2Publication Date: 2012-01-03
- Inventor: Thomas M. Bradicich , Richard E. Harper , William J. Piazza
- Applicant: Thomas M. Bradicich , Richard E. Harper , William J. Piazza
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Carey, Rodriguez, Greenberg & O'Keefe
- Agent Steven M. Greenberg, Esq.
- Main IPC: G06F11/00
- IPC: G06F11/00

Abstract:
Embodiments of the present invention provide a method, system and computer program product for the heuristic malware detection. In one embodiment of the invention, a heuristic malware detection method can include merging a baseline inventory of file attributes for respective files from each client computing system in a community of client computing systems into a merged inventory. The method further can include receiving an updated inventory of file attributes in a current inventory survey from different ones of the client computing systems. Each received survey can be compared to the merged inventory, and in response to the comparison, a deviant pattern of file attribute changes can be detected in at least one survey for a corresponding client computing system. Thereafter, the deviant pattern can be classified as one of a benign event or a malware attack. Finally, malware removal can be requested in the corresponding client computing system if the deviant pattern is classified as a malware attack.
Public/Granted literature
- US20080141371A1 HEURISTIC MALWARE DETECTION Public/Granted day:2008-06-12
Information query